Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Gamaredon fileless WinRAR intrusion chain in Ukrainian state and infrastructure networks

Updated 01.06.2026 14:00
Case score 56
Case score 56 Members 1 Latest activity 01.06.2026 14:00
Members 1 First seen 01.06.2026 14:00 Last seen 01.06.2026 14:00 Updated 01.06.2026 14:00

Overview

**Gamaredon** remained active in January 2026 against **Ukrainian government, military, and critical-infrastructure** networks, using a booby-trapped xHTML file and malicious RAR archive to exploit **CVE-2025-8088** in **WinRAR**. The intrusion chain places a hidden HTA file in Startup, leans on **fileless VBScript**, stores components in **NTFS Alternate Data Streams**, and uses dead-drop resolvers on **Telegram** and **Cloudflare** to support long-term access and document theft. Defensive focus has shifted to patching **WinRAR** to **7.13 or later** and hunting for startup-folder HTA files, alternate data streams, suspicious VBScript, scheduled tasks, registry changes, and removable-media spread. The activity is ongoing, but available evidence does not quantify how many organizations were compromised or how much data was taken.